CYBER SECURITY FINAL EXAM QUESTIONS AND
CORRECT ANSWERS
Risk Mangement - Answers - the practice of identifying, evaluating and prioritizing risk
followed by the application of resources to minimize, monitor and control probability of
the risk and/ or their business impacts.
Cybersecurity Risk Management - Answers - is a set of policies, processes, and
controls to protect the organization's information assets from security incidents.
Who leads Cybersecurity Risk Management? - Answers - CIO
CISO
other IS managers
Risk Assessment - Answers - 1. Identify and analyze potential risk that may negatively
impact an organization or its stakeholders
2. make judgment on the acceptance or tolerability of the risks.
Framework for Risk Assessment - Answers - Risk identification: vulnerability
Risk estimation: level or severity
Risk evaluation: business impact
Risk Assessment Formula - Answers - Cybersecurity risk=f(vulnerability, severity,
impact)
vulnerability - Answers - is the likelihood of a cybersecurity incident
Severity - Answers - the level of risk associated with the incident
Impact - Answers - the business loss caused by the incident
National Cyber Incident Scoring System (NCISS) - Answers - is designed to provide a
repeatable and consistent mechanism for estimating the risk of an incident.
Risk Treatment Strategies - Answers - Risk Reduction (Defense and Mitigation)
Risk transference
Risk acceptance
Risk termination
, Defense (avoidance) - Answers - attempts to prevent the exploitation of the
vulnerability.
Mitigation - Answers - is the treatment approach that focuses on planning and
preparation to reduce the impact or potential consequences of an incident or disaster.
Common Defense Methods? - Answers - Application of policy (e.g., ISP)
Application of SETA programs
Implementation of technology
4 Mitigation Plans - Answers - Business continuity (BC) plan
Disaster recovery (DR) plan
Incident response (IR) plan
Crisis Management (CM) plan
Business Continuity Plan - Answers - a set of policies, tools and procedures, or plan, to
enable an organization to continue the delivery of goods and/or services at pre-defined
acceptable levels following a disruptive incident
Disasters Recovery - Answers - a set of policies, tools and procedures to enable the
recovery or continuation of vital technology infrastructure and systems following a
natural or human-induced disaster.
Incident Response - Answers - is a set of policies, tools and procedures to dictate an
organization's reactions to a cybersecurity incident such as attack.
Crisis Management - Answers - a set of policies, tools and procedures by which an
organization deals with a disruptive and unexpected event that threatens the
organization or its stakeholders.
Transference - Answers - risk treatment strategy attempts to shift risk to another entity.
Service Level Agreement (SLA) in Outsourcing - Answers - key to an effective
transference risk control strategy
4 Steps to Create a successful SLA - Answers - Determining objectives: What is/are the
services(s) to be outsourced? What do they do?
Defining requirements: What are the requirements or specifications of the services?
Setting measurements: How is the performance measured?
CORRECT ANSWERS
Risk Mangement - Answers - the practice of identifying, evaluating and prioritizing risk
followed by the application of resources to minimize, monitor and control probability of
the risk and/ or their business impacts.
Cybersecurity Risk Management - Answers - is a set of policies, processes, and
controls to protect the organization's information assets from security incidents.
Who leads Cybersecurity Risk Management? - Answers - CIO
CISO
other IS managers
Risk Assessment - Answers - 1. Identify and analyze potential risk that may negatively
impact an organization or its stakeholders
2. make judgment on the acceptance or tolerability of the risks.
Framework for Risk Assessment - Answers - Risk identification: vulnerability
Risk estimation: level or severity
Risk evaluation: business impact
Risk Assessment Formula - Answers - Cybersecurity risk=f(vulnerability, severity,
impact)
vulnerability - Answers - is the likelihood of a cybersecurity incident
Severity - Answers - the level of risk associated with the incident
Impact - Answers - the business loss caused by the incident
National Cyber Incident Scoring System (NCISS) - Answers - is designed to provide a
repeatable and consistent mechanism for estimating the risk of an incident.
Risk Treatment Strategies - Answers - Risk Reduction (Defense and Mitigation)
Risk transference
Risk acceptance
Risk termination
, Defense (avoidance) - Answers - attempts to prevent the exploitation of the
vulnerability.
Mitigation - Answers - is the treatment approach that focuses on planning and
preparation to reduce the impact or potential consequences of an incident or disaster.
Common Defense Methods? - Answers - Application of policy (e.g., ISP)
Application of SETA programs
Implementation of technology
4 Mitigation Plans - Answers - Business continuity (BC) plan
Disaster recovery (DR) plan
Incident response (IR) plan
Crisis Management (CM) plan
Business Continuity Plan - Answers - a set of policies, tools and procedures, or plan, to
enable an organization to continue the delivery of goods and/or services at pre-defined
acceptable levels following a disruptive incident
Disasters Recovery - Answers - a set of policies, tools and procedures to enable the
recovery or continuation of vital technology infrastructure and systems following a
natural or human-induced disaster.
Incident Response - Answers - is a set of policies, tools and procedures to dictate an
organization's reactions to a cybersecurity incident such as attack.
Crisis Management - Answers - a set of policies, tools and procedures by which an
organization deals with a disruptive and unexpected event that threatens the
organization or its stakeholders.
Transference - Answers - risk treatment strategy attempts to shift risk to another entity.
Service Level Agreement (SLA) in Outsourcing - Answers - key to an effective
transference risk control strategy
4 Steps to Create a successful SLA - Answers - Determining objectives: What is/are the
services(s) to be outsourced? What do they do?
Defining requirements: What are the requirements or specifications of the services?
Setting measurements: How is the performance measured?